Medium1 markMultiple Choice

AZ-305 · Question 08 · Domain 1.2: Authentication and Authorization

A company with strict security policies requires that user passwords must never be synchronized to the cloud, not even in a hashed format. They want to implement Single Sign-On (SSO) for Microsoft 365 and Azure applications using their on-premises Active Directory. Which hybrid identity authentication method should you recommend?

Answer options:

A.

Password Hash Synchronization (PHS).

B.

Pass-through Authentication (PTA).

C.

Azure AD Domain Services.

D.

Microsoft Entra B2B.

How to approach this question

Identify the hybrid auth method that validates credentials on-premises without syncing hashes.

Full Answer

B.Pass-through Authentication (PTA).✓ Correct
Pass-through Authentication (PTA).
Pass-through Authentication (PTA) allows users to sign in to both on-premises and cloud-based applications using the same passwords, validating them directly against on-premises Active Directory without storing hashes in the cloud.

Common mistakes

Choosing PHS, which explicitly violates the 'no hash sync' requirement.

Practice the full Azure Solutions Architect Expert AZ-305 Practice Exam 6

55 questions · hints · full answers · grading

More questions from this exam